How Qrtr protects user data
We limit access to user data, separate responsibilities, and use monitoring to help us notice unusual activity. Access is granted only when it is needed for a specific job and is reviewed as the product changes.
- We collect and keep only what we need to provide Qrtr.
- We use access controls and secrets management for internal systems.
- We log important system events and investigate suspicious activity.
- We maintain backups and recovery processes so we can restore service safely.
Encryption
Qrtr encrypts information while it moves between your device, our services, and our service providers using modern TLS protections.
We also use encryption at rest where supported by our infrastructure and vendors. Encryption is one layer of protection, so we pair it with access controls, monitoring, secure development practices, and careful vendor management.
Authentication
Your Qrtr account is protected by secure credential handling and session controls. We do not store bank passwords in Qrtr. Keep your email account and Qrtr login details private, use a unique password, and contact us quickly if something looks wrong.
As additional sign-in options become available, we will make them easy to enable from your account settings.
Bank connections
When you connect a bank, Qrtr works with Plaid or another authorized connection provider. The provider handles the bank sign-in flow and gives Qrtr the account information you approve. Qrtr does not ask for or store your bank username or password.
You can disconnect a connection from Qrtr when the product supports it, or ask support@qrtr.app for help. Disconnecting Qrtr does not necessarily close your bank account or delete information held by the connection provider.
Infrastructure overview
Qrtr runs on managed cloud infrastructure with separate application, data, and operational controls. We use reputable providers for hosting, database services, email, bank connectivity, and error monitoring, and we review those providers as the product grows.
We test changes before release, keep dependencies under review, and work to reduce the amount of sensitive information exposed to any one system.
Responsible disclosure
If you think you have found a security issue, please do not publicly share the details before we have had a chance to investigate. Email security@qrtr.app with what you found, where you found it, and steps to reproduce it if you can.
We will acknowledge reports as soon as we can, investigate in good faith, and keep you updated when the issue is actionable. Please do not access, change, or delete other people’s data while testing.